Security

Security and responsible disclosure

We take security seriously. If you find a vulnerability, we appreciate responsible disclosure so we can investigate and fix issues quickly.

Report a vulnerability

Email security@sightwhale.com with a clear description, reproduction steps, and impact assessment. If possible, include:

  • Affected URL(s) and request/response samples (redact secrets)
  • Steps to reproduce and expected vs. actual behavior
  • Proof of concept (PoC) with minimal risk
  • Suggested remediation, if you have one

Safe harbor

We welcome good-faith security research. Please avoid actions that could harm users or the platform, such as data exfiltration, service disruption, or social engineering.

Scope

  • In scope: sightwhale.com and official subdomains/services
  • Out of scope: third-party services not controlled by Sight Whale

What we do

  • We triage reports and respond as quickly as practical
  • We prioritize fixes by severity and exploitability
  • We may request additional details to validate impact

User data

Never send us secrets (API keys, passwords, private keys). If you believe you have found exposed data, stop and contact us immediately.